Table of contents exchange of letters with the minister executive summary


Informing SingHealth’s management, MOH, the Chairman of



Download 5.91 Mb.
View original pdf
Page157/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   153   154   155   156   157   158   159   160   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019

29.4 Informing SingHealth’s management, MOH, the Chairman of
the SingHealth Board, and the Chairman of the Risk Oversight
Committee
588. At pm on 10 July 2018, Benedict emailed Prof. Ivy, Prof. Kenneth, Tan Jack Thian (“Jack Thian”) (SingHealth’s Group COO, and Loo Chian Min
(SingHealth’s Medical Informatics Officer, informing them that IHiS “detected
unauthorised accesses to the SCM production database” on 4 July 2018, that the team immediately terminated/blocked all the programs and access channels on
4 July 2018, and that IHiS was now doing forensics to determine the source/cause and if any data was compromised. Benedict also provided a summary of events relating to the incident known to IHiS up to that point, and asked for the recipient’s advice on whether to inform the MOH Integrated Operations Hub (the “MOH Ops Centre”) through Jack Thian. Prof. Ivy replied
via email on pm, stating that this is very serious indeed, and asked that the MOH Ops Centre be informed in accordance with protocol. Thereafter, Benedict worked with Jack Thian to prepare the incident report to the MOH Ops Centre.



COI Report – Part IV
Page 185 of 425

589. Separately, at pm on 10 July 2018, Bruce sent an email to (i) the Permanent Secretary of Health, Mr Chan Heng Kee; (ii) the MOH Director of Medical Services, Associate Professor Benjamin Ong; (iii) the Deputy Secretary Policy) of Health, Ms Ngiam Siew Ying; and (iv) the Managing Director of
MOHH, Aik Guan. In this email, Bruce informed the recipients of “a potential
EMR systems breach”, and provided an interim update on IHiS’ investigation findings. In addition, Bruce analysed the situation as such in his email:
Our Citrix servers and SCM EMR database servers are likely to have been attacked and breached by a highly sophisticated & intelligent hacking ops. The attacker demonstrated significant understanding of
Citrix, SCM and our physical computing infrastructure. We noticed database retrieval commands (SQLs) to SCM database were made but we are trying to locate evidence that the commands were successfully executed and records accessed. There's likely a system security breach but we can't confirm a data breach. But if the data accesses were successful, it would be very serious as up to K dispense medication records could have been accessed.
590. At pm on 10 July 2018, SingHealth submitted a formal incident report to MOH Ops Centre via email. The email was titled “Incident Report to MOH –
2018/02/01 (Initial Report) on Unauthorized Access to SCM Production
Database””. The report stated that the incident was assessed to be a Category 1 incident, and contained a summary of the facts known to IHiS at the time.
591. On 11 July 2018, the Chairman of the SingHealth Board and the Chairman of the Risk Oversight Committee were informed of the Cyber Attack.

Download 5.91 Mb.

Share with your friends:
1   ...   153   154   155   156   157   158   159   160   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page